Web Shell Upload via Content-Type Restriction Bypass

Опубликовано: 07 Май 2026
на канале: Intigriti
34,933
267

👩‍🎓👨‍🎓 Learn about File Upload vulnerabilities. This lab attempts to prevent users from uploading unexpected file types, but relies on checking user-controllable input to verify this. To solve the lab, we'll upload a basic PHP web shell and use it to exfiltrate the contents of a "secret" file.

Overview:
0:00 Intro
0:18 Background: File upload vulnerabilities
4:59 Background: Flawed file type validation
6:37 Challenge info
7:22 Attempt PHP webshell upload
8:20 Content-type restriction bypass
9:30 Remediations
10:46 Conclusion

For more information, check out https://blog.intigriti.com/hackademy/...

🔗 ‪@PortSwiggerTV‬ challenge: https://portswigger.net/web-security/...

🧑💻 Sign up and start hacking right now - https://go.intigriti.com/register

👾 Join our Discord - https://go.intigriti.com/discord

🎙️ This show is hosted by   / _cryptocat   ( ‪@_CryptoCat‬ ) &   / intigriti  

👕 Do you want some Intigriti Swag? Check out https://swag.intigriti.com